Reporting

view report with one instance of a specific version

patrick79
Explorer

I am trying to create a report that pulls a version, but only shows one instance and then list all the hosts within that version

patrick79_0-1713363255097.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Assuming you already have the fields extracted:

<your index search>
| stats count by Name Version host
| eventstats count by Name Version
| eventstats max(count) as top
| where count=top

View solution in original post

patrick79
Explorer

I am searching for "Unified Payment Platform Version=" which contains the specific version of firmware from about 2000+ hosts. 
The line I am searching may populate multiple times depending on if the device was rebooted.

The search I need:
 - list all the versions, but only one count from each host
 - if possible, the list the hosts on the version

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some anonymised representative events in raw format in a code block </>

0 Karma

patrick79
Explorer

[2024-04-17 10:23:37] [Lane 0] Application ID: Name=Unified Payment Platform Version=06.80.06-0032

 

patrick79_0-1713371287284.png

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming you already have the fields extracted:

<your index search>
| stats count by Name Version host
| eventstats count by Name Version
| eventstats max(count) as top
| where count=top

ITWhisperer
SplunkTrust
SplunkTrust

You could try something like this

<your index search>
| eventstats count by Version
| eventstats max(count) as top
| where count=top
0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...